CONFIDENTIAL · BY APPOINTMENT
v. 2026.05 UTC+01 · FRANKFURT AM MAIN
OPENING BRIEF

A boutique advisory for institutions whose security answers to supervisors.

Momental is a small, partner-led advisory for banks, insurers, asset managers and regulated technology firms. We do four things: assessments & compliance, identity & privileged access, threat detection & response, and growth-stage strategy. Each engagement is conducted as a closed file.

§ 01Practice

Four disciplines, kept under one roof.

A coherent practice, not a menu. Each engagement borrows the parts it needs and leaves the rest, but the disciplines are taught — and conducted — together.

01
Assessments
& Compliance

Security Assessments & Compliance

Structured reading of your security posture against standards your supervisors actually use. The output: a defensible target picture, sequenced plan, named owners.

  • Regulatory readiness (DORA, NIS2)
  • ISMS to ISO/IEC 27001:2022
  • GRC strategy & data protection
02
Identity
& Access

Identity & Privileged Access

IAM and PAM are the spine of the modern security architecture. We design and steward the introduction — strategy to retirement of legacy components.

  • PAM strategy & tool selection
  • Decommissioning end-of-life systems
  • Permission & role models
03
Detection
& Response

Threat Detection & Response

Detect incidents before they escalate; respond with composure. We design monitoring, incident and change processes and govern managed-service vendors by KPI.

  • Monitoring & detection concepts
  • Incident & change management
  • Managed-service stewardship
  • Contract negotiation & delivery governance
04
Strategy
& Growth

Strategy & Growth Advisory

Advice during growth phases, market entry and valuation moments. Drawn from years inside DAX-40 banks and tier-one consultancies.

  • Go-to-market & market-entry strategy
  • Business development & market analysis
  • Valuation & IPO readiness
  • Operational accompaniment in expansion
§ 02Engagement models

Advice with tenure, not by project.

Where the discrete project does not suffice, two recurring engagements anchor strategic security at C-level — planned, confidential, partner-led.

RETAINER
Model A · monthly

Fractional CISO

For growth companies, Mittelstand and PE portfolio holdings without a CISO of their own — yet under regulatory or contractual pressure.

Defined monthly hour allocation
Representation as CISO toward board, supervisor, clients
Strategic ISMS stewardship & audit accompaniment
Escalation readiness during incidents
Quarterly reporting to executive board
MENTORING
Model B · monthly

Executive Mentoring

For CISOs, Heads of Cyber and IT leaders in regulated industries who want sparring at eye-level — without the apparatus of a consulting project.

Two 90-minute one-to-ones each month
Preparation of critical board & supervisor moments
Career advice & stakeholder strategy
Availability for short questions between sessions
§ 03Approach

Pragmatic in method. Consequential in effect.

Security that endures in regulated industries requires more than a framework. It requires clarity on risks, discipline in execution, and a model that scales with the institution.

01

Regulatorily fluent

Working knowledge of DORA, NIS2 and ISO/IEC 27001 — as a shared language between business, IT and supervisor.

02

An AI-augmented boutique

Proprietary AI workflows accelerate assessments, policy review, regulatory mapping and reporting — delivering tier-one depth at boutique scale.

03

Managed-service-first

Where sensible, we lean on established managed services — with clear KPIs and stewardship that surfaces risks rather than masking them.

04

From concept to handover

Strategy, architecture, implementation and operational handover from one office — without seams between advisory and realisation.

05

Documented to audit standard

Every measure is documented so it withstands internal and external review — BaFin, EZB, MAS.

06

Single-thread partner

Each engagement is conducted by one partner, by appointment. No rotating juniors. No handoffs at deliverable boundaries.

§ 04Dossier · anonymised

Files closed. References on request.

Engagements are described without the client's name. References are exchanged in private, after a short introductory conversation.

EngagementScopeSectorYr.
DORA readiness across a European insurer's ICT estate ISMS · ICT-risk · third-party Insurance · Group 2026
PAM replatforming for a DAX-40 bank — CyberArk to scale PAM · IAM · decom Banking · Tier-One 2025
Threat-detection KPI model for a regulated cloud provider SOC · KPI · vendor mgmt Cloud · MAS-supervised 2025
Fractional CISO mandate, PE-held asset manager CISO · board reporting Asset Mgmt · PE-held 2024–
ISMS to ISO 27001 inside a fintech preparing IPO ISMS · 27001 · IPO-ready Fintech · Pre-IPO 2024
Decommissioning end-of-life IAM at a custody bank IAM · legacy retirement Custody · Tier-Two 2023
§ 05The office

A team, no monopolies.

Momental is conducted by partners, principals and senior advisors who have spent careers inside the institutions they now advise. The strength of the firm is the strength of the team — not the résumé of any one of us.

The Practice Senior advisors across every engagement.

Every engagement is led and delivered by senior practitioners — no rotating juniors, no anonymous output chains. Where specialist research or analysis supports the work, it is sourced deliberately, curated by the lead advisor, and fully accountable. The disciplines were learned at DAX-40 banks, tier-one consultancies and regulated technology firms; the judgment stays in Frankfurt am Main, by appointment.

Disciplines4 core practices CoverageCross-sector LanguagesDE · EN
§ 06About the office

The firm, in five sentences.

Five principles we keep posted by the door. They are not slogans; they are arguments we have had with ourselves and won.

Momental was founded in 2024 as a small, partner-led advisory for institutions whose security must answer to regulators and boards. We work in single threads, by appointment. The output is rarely a deck — it is usually a decision, written in a way that survives the next audit.

Quietude

A small office is freer than a large one. We are deliberately under-marketed.

Tenure

Relationships measured in years, not engagements measured in weeks.

Plainness

If a finding cannot be written in a sentence a non-technical board member can repeat, it is not finished.

Discipline

Every measure documented to audit standard — to be ready for the supervisor, not to flatter them.

Refusal

We turn down work that would dilute the practice. The engagements we have declined are, quietly, the proof.

§ 07Open a channel

Write to the office.

Whether you carry a defined mandate or only a question worth asking, the simplest start is a short note.

A short letter is always enough.

Tell us, in a paragraph, the situation as you understand it. We will write back with three questions and a time.

→   [E-Mail]
CHANNEL · OPENUTC+01
Channel[E-Mail]
OfficeFrankfurt am Main
EngagementsDelivered on-site, hybrid or remote — wherever the client requires